MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 68e3594b43bbde6e828727df2f6644d47efb75540c41e5644a73015a1d75f6d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 68e3594b43bbde6e828727df2f6644d47efb75540c41e5644a73015a1d75f6d0
SHA3-384 hash: 05382fbad98cfad15bcfbc32939957d707dcc635d0617089ff664b8fc395f1dead15109b3b66ce9e31a5aae4edfb2ca5
SHA1 hash: b691ac1cdbe18df6eb8d0968ee71486738372356
MD5 hash: 9dc4803f42b4007726faa2023efb3163
humanhash: speaker-ceiling-item-connecticut
File name:h
Download: download sample
File size:470 bytes
First seen:2026-02-03 18:31:49 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:4AeVMI8b8zuXMuDuGutjAYbDy4gQesFrFBEGgcu+yfuT+JF8EpASLye:EVoQyXliTiSBRrTBEG6TuyLpvR
TLSH T1CCF0825FF308C9FAE93A058E3A983DCC61AE526CCE6E1A151E341E56A48585C64C1037
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Clean
File Type:
ps1
First seen:
2026-02-03T15:52:00Z UTC
Last seen:
2026-02-03T16:40:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=78dae936-1b00-0000-9534-31f7990b0000 pid=2969 /usr/bin/sudo guuid=d5355239-1b00-0000-9534-31f7a00b0000 pid=2976 /tmp/sample.bin guuid=78dae936-1b00-0000-9534-31f7990b0000 pid=2969->guuid=d5355239-1b00-0000-9534-31f7a00b0000 pid=2976 execve
Threat name:
Script-Shell.Downloader.MiraiB
Status:
Malicious
First seen:
2026-02-03 18:23:04 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 68e3594b43bbde6e828727df2f6644d47efb75540c41e5644a73015a1d75f6d0

(this sample)

  
Delivery method
Distributed via web download

Comments